Cross-Site Scripting Vulnerability in Leetoo Toocheke Companion Plugin
CVE-2025-23992

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 January 2025

What is CVE-2025-23992?

The Leetoo Toocheke Companion plugin for WordPress is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts. This issue affects versions from n/a up to 1.166, enabling stored XSS attacks where the malicious code is saved and executed when other users access the compromised page. Website owners using this plugin should prioritize patching or updating to mitigate the risk of potential exploitation.

Affected Version(s)

Toocheke Companion 0 <= 1.166

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pham Van Tam (Patchstack Alliance)
.